Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Data & methods

Methodology, sources, and standards.

Institutional research authority rests on documented practice. This page describes SCRI's standing methodology, source channels, known limitations, versioning behavior, and citation policy. The same rules apply to every publication.

Methodology

How SCRI works.

SCRI operates in three modes. Foundational papers construct analytical frameworks (cost models, risk functions, transparency indices) grounded in the published literature and calibrated against a multi-year breach dataset. The quarterly seriesapplies those frameworks empirically to each new quarter's incident record. Playbook and coverage material translates the frameworks and quarterly findings into practitioner-facing analysis. All three modes publish with sources, methods, limitations, and version metadata.

The underlying data compilation is multi-source. Each incident is deduplicated across the channels below before it enters the analytical dataset. Where multiple sources report different affected-population figures for the same incident, the most recent publicly available figure is used, with the full revision history preserved in the working copy.

Data sources

Seven authoritative channels feed the compilation.

HHS OCR Breach Portal

Federal breach-notification database. Complete for the 500+ affected-individuals threshold, but underweight in the immediate aftermath of shutdown periods and heavily dependent on covered-entity self-reporting cadence.

State Attorney General filings

State AG breach-notification filings (notably Oregon, California, Vermont). Frequently first to surface material breach detail before the OCR portal update.

CISA advisories

Sector alerts, known-exploited-vulnerability announcements, and joint federal advisories referencing healthcare-sector activity.

FTC enforcement records

Health data enforcement outside HIPAA scope — consumer app breaches, non-covered-entity health data mishandling, deceptive practices.

Primary entity disclosures

Covered-entity and business-associate press releases, SEC 8-K filings for public companies, and formal individual-notification correspondence when publicly circulated.

Dark-web market observations

Aggregated pricing observations sourced from published Intel 471, Recorded Future, and Flashpoint reporting. Direct market monitoring is out of scope.

Ransomware leak-site publication

Named-group leak-site publications treated as public-disclosure events. Frequently precede formal regulatory notification by weeks or months.

Limitations

What the compilation does not capture.

Public-record dependence

SCRI research is bounded by what enters the public record. Under-reported or classified incidents are structurally absent from the dataset.

Revision volatility

Affected-individual figures often revise upward months after initial disclosure. Analytical snapshots are timestamped to the compilation date.

Attribution asymmetry

Threat-actor attribution is sourced from public reporting where available. In many cases, attribution is not made public and is not asserted.

Selection in cost outcomes

Published cost outcomes are drawn from litigated or otherwise publicly disclosed incidents, which are not representative of the full incident population.

Versioning & corrections

Every publication carries a version.

Each SCRI publication is issued with a version identifier (v1.0, v1.1, etc.) and a modification date. Non-material revisions increment the minor version. Material corrections — factual, numerical, or interpretive — are accompanied by a published correction notice on the publication page. Prior versions remain accessible for the record.

Reader-submitted corrections are welcomed. Substantiated corrections are addressed in the next scheduled revision or, for material issues, an out-of-cycle correction.

Citation & reuse

Cite freely. Attribute clearly.

Permitted uses of SCRI research include academic citation with full attribution, fair-use quotation for commentary or news reporting, and sharing of the published PDF in its complete and unaltered form. Every publication page provides APA, Chicago, and BibTeX citation blocks.

SCRI datasets published on GitHub (the HIPAA Toolkit and HIPAA Shield extensions) are released under Creative Commons Attribution 4.0 (CC BY 4.0). Attribution should name the Secure Care Research Institute and Patient Protect LLC.